Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.1
CVE-2021-22936
A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated admin…
Connect Secure
9.1+
HIGH 7.2
CVE-2021-3198
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issu…
Mobileiron
11.1.0.0+
HIGH 7.2
CVE-2021-3540
By abusing the 'install rpm info detail' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. T…
Mobileiron
11.1.0.0+
HIGH 8.8
CVE-2021-22908EPSS 69%
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shar…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2021-22894 KEVEPSS 41%
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2021-22899 KEVEPSS 23%
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut…
Connect Secure
Mitigation only
HIGH 7.2
CVE-2021-22900 KEVEPSS 14%
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to pe…
Connect Secure
after 9.1
CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2020-13769
LDMS/alert_log.aspx in Ivanti Endpoint Manager through 2020.1 allows SQL Injection via a /remotecontrolauth/api/device request.
Endpoint Manager
after 2020.1
MEDIUM 5.4
CVE-2020-13773
Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_l…
Endpoint Manager
after 2020.1.1
MEDIUM 5.3
CVE-2020-13772
In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, l…
Endpoint Manager
after 2020.1.1
CRITICAL 9.9
CVE-2020-13774
An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…
Endpoint Manager
Mitigation only
HIGH 7.8
CVE-2020-13770
Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as thes…
Endpoint Manager
after 2020.1.1
HIGH 7.8
CVE-2020-13771
Various components in Ivanti Endpoint Manager through 2020.1.1 rely on Windows search order when loading a (nonexistent) library file, allowing (unde…
Endpoint Manager
after 2020.1.1
HIGH 7.2
CVE-2020-8260 KEVEPSS 96%
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution …
Connect Secure
after 9.0
MEDIUM 6.1
CVE-2020-8262
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Re…
Connect Secure
9.1+
HIGH 7.2
CVE-2020-15352
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authen…
Connect Secure
after 9.0
HIGH 7.2
CVE-2020-8243 KEVEPSS 91%
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform …
Connect Secure
after 9.0
MEDIUM 6.1
CVE-2020-8238
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cr…
Connect Secure
after 9.0
CRITICAL 9.8
CVE-2020-12441
Denial-of-Service (DoS) in Ivanti Service Manager HEAT Remote Control 7.4 due to a buffer overflow in the protocol parser of the ‘HEATRemoteService’ …
Desktop\&server Management
2020.1+
CRITICAL 9.8
CVE-2020-13793
Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.
Dsm Netinst
Mitigation only
MEDIUM 6.8
CVE-2020-8222
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to pe…
Connect Secure
after 9.0
HIGH 8.1
CVE-2020-8206
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the…
Connect Secure
after 9.0
HIGH 7.2
CVE-2020-8218 KEVEPSS 32%
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution …
Connect Secure
after 9.0
HIGH 7.2
CVE-2020-8219
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full adminis…
Connect Secure
after 9.0
MEDIUM 6.5
CVE-2020-8220
A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the ad…
Connect Secure
after 9.0
MEDIUM 6.1
CVE-2020-8204
A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
Connect Secure
after 9.0
MEDIUM 5.4
CVE-2020-8217
A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.
Connect Secure
after 9.0
MEDIUM 5.5
CVE-2020-12880
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel …
Connect Secure
after 9.0
HIGH 7.8
CVE-2019-17066
In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because …
Workspace Control
10.4.40.0+